Arbitrary Code Execution Vulnerability in Zed IDE by Zed Industries
CVE-2025-68432

7.8HIGH

Key Information:

Status
Vendor
CVE Published:
17 December 2025

What is CVE-2025-68432?

The Zed IDE, a popular code editor, contains a vulnerability that allows for arbitrary code execution through manipulated Language Server Protocol (LSP) configurations. If a user unwittingly opens a project containing a malicious settings.json file located in the project's .zed subdirectory, an attacker could execute arbitrary shell commands with the user's privileges. The vulnerability is triggered when the IDE loads these configurations upon opening the project file. To mitigate this risk, version 0.218.2-pre introduces a worktree trust mechanism, while users are advised to thoroughly examine the contents of any project settings file before opening projects in Zed.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

zed < 0.218.2-pre

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.